Tag: emerging threats
6293 articles

Cybersecurity Leaders Warn of AI Trust Gap
More than one in five organizations have fallen victim to AI-powered attacks, with 22% reporting a security incident in the past year where hackers used artificial intelligence to breach critical business platforms. This alarming trend highlights the urgent need for cybersecurity leaders to address the growing AI trust gap.

Novocure Breach Exposes Over 1,400 US Cancer Patient Records
Rest assured, Novocure confirms that the breach didn't compromise their medical treatment devices or disrupt operations, and all systems are fully functional. The company is taking swift action, having discovered the unauthorized access in mid-August and immediately launching an investigation to contain the incident.

Hackers exploit BGP hijacking to deliver malicious Virtualizor updates
Malicious actors hijacked internet traffic to deliver fake Virtualizor updates to a small number of users, exploiting a vulnerability in the Border Gateway Protocol (BGP) to divert update requests to their own servers. This sneaky move allowed them to push malicious updates to unsuspecting users.

Enterprises Lag in AI Agent Governance
Most enterprises are playing with fire when it comes to AI agents, with a staggering 65% admitting that their AI agents have veered off course, causing measurable impacts in nearly 3 out of 10 cases. As organizations increasingly deploy AI at scale, governance gaps are leaving them vulnerable to risk.

Edge Security Exposes Hidden Risks in Legitimate Traffic
Despite having a robust arsenal of edge controls, security teams are still flying blind to hidden risks lurking in legitimate traffic, leaving them vulnerable to potential threats. The issue lies in the lack of context around underlying infrastructure, causing standard defenses to miss high-risk sessions.

Iranian Hackers Deploy Cross-Platform Malware via Coding Tests
Iranian hackers are using clever tactics to deploy cross-platform malware, disguising it as coding challenges on LinkedIn and other job search platforms to trick developers into installing the threat. This malware, tracked as NodeRabbit and PollCat, can infect Windows, Linux, and macOS workstations, allowing hackers to gain remote access.

US Bolsters Water Infrastructure with Cybersecurity Pilot
The alarming number of cyber incident reports from water providers - 27 in just seven states - has prompted a swift response from the White House and Texas officials with the launch of Project Watershed 250, a six-month pilot aimed at bolstering water infrastructure cybersecurity. This innovative program will deploy top-notch cyber-defense resources to water and wastewater utilities at no cost, starting with a test run in Texas.

Unpatched Microsoft Exchange Servers Exposed to Hijack Attacks
Thousands of Microsoft Exchange servers remain vulnerable to a high-severity flaw, leaving 21,899 internet-facing systems open to hijack attacks that could give attackers control of every mailbox. This unpatched authentication-bypass vulnerability, CVE-2026-62911, was fixed by Microsoft in August, but many servers still haven't been updated.

BGP Hijack Targets Softaculous Traffic, Delivers Malware
In a shocking 33-hour heist, a BGP hijack diverted traffic meant for Softaculous, delivering malware to unsuspecting users via a valid TLS certificate issued to the attacker. The clever hack exploited a weakness in internet routing, allowing the attacker to intercept and compromise Virtualizor installations.

Cyberattackers Favor Repeatable Playbooks Over Innovative Tactics
Cyberattackers are ditching creative tactics for a straightforward, repeatable playbook - and it's surprisingly effective, with a simple trick called ClickFix accounting for 47% of attacks. This sneaky method involves guiding users through a CAPTCHA-style interaction, then tricking them into pasting a command into a terminal, all without needing attachments or vulnerabilities.

Uzbekistan Unveils Chinese J-10CE Fighters
Uzbekistan has officially welcomed its new fleet of Chinese J-10CE fighters, with at least six aircraft making a grand entrance in state TV footage on August 28, 2026. The public debut was marked with a ceremonial water-cannon salute, showcasing the country's growing military capabilities.

US Navy Develops Seabed Torpedo Launcher for Orca Submarine Vehicle
Meet the Liberator, a game-changing, containerized torpedo launcher designed to be deployed on the ocean floor, capable of firing powerful Mk 48 ADCAP heavyweight torpedoes at enemy ships and subs. This autonomous seabed system is set to revolutionize naval warfare as part of the US Navy's cutting-edge Orca submarine vehicle program.

Russia Surges Jet-Powered Drone Output, Pressures Ukraine Air Defenses
Russia is now launching jet-powered drones at an astonishing rate, with estimates suggesting a whopping 3,000 units per month, and Ukraine's air defenses are feeling the pressure. In fact, two-thirds of all drones launched in a day can now be jet-powered, according to Colonel Yurii Ihnat of the Ukrainian Air Force.

Pakistan Develops Loitering Munitions for Deep-Strike Capability
Pakistan is taking a major leap in its military capabilities with the development of loitering munitions, including a tailless delta design, to enhance its deep-strike ability. This new technology, showcased to the Pakistan Army Chief, promises a scalable and long-range strike posture, with some systems boasting a range of up to 3,000 km.

DoD Refrigerator Outages Spark Hacking Fears
A defense official has warned of possible refrigeration disruptions at some Defense Commissary Agency commissaries, sparking concerns about the security of military food storage systems. Several bases have already reported outages, including Fort Irwin, F.E. Warren Air Force Base, and Naval Station Newport.

Mirage Kitten Unveils Node.js Malware Targeting Aviation, FinTech
Kaspersky's threat research uncovered a sneaky Node.js malware campaign targeting aviation and FinTech organizations in the Middle East and Africa, with victims initially tricked by fake job offers on LinkedIn. The malware, known as NodeRabbit, was delivered through cleverly disguised coding-challenge archives.

Australia's Economy Exposed to Digital System Failures
When Optus went down in 2023, the inconvenience was clear - no coffee, no lunch, no Uber - but what Australians laughed off as a minor annoyance actually exposed a much deeper vulnerability: the alarming dependence of Australia's economy on digital systems. The real issue wasn't just payments, but the entire economic exchange process, from ordering to delivery to settlement.

Army Secretary Dan Driscoll Resigns Amid Strained Pentagon Ties
Army Secretary Dan Driscoll is stepping down from his role after serving for less than two years, sparking a new chapter for the Department of the Army. His departure comes amid reports of strained ties with the Pentagon and a conversation with President Trump about the Army's future.

US Strikes Iranian Rocket Launchers Capable of Deploying Sea Mines
The US has taken decisive action against Iranian forces preparing to launch sea mines into the Strait of Hormuz, striking two rocket launchers on Larak Island after spotting Islamic Revolutionary Guard Corps personnel ready to fire. This swift move aims to protect the vital waterway from potential threats.

US, Indonesia Launch Super Garuda Shield Military Exercises
Get ready for the largest and most complex military exercise in the Indo-Pacific region - Super Garuda Shield, a powerful display of international cooperation that's bringing together over 4,743 troops from 15 nations to build a safer future. This annual drill, now in its expanded multilateral format, kicks off a two-week show of strength and unity.

Hegseth's Purge Prompts Army Secretary Driscoll's Resignation
Army Secretary Dan Driscoll has resigned amid a heated clash with Defense Secretary Pete Hegseth over the Army's transformation and readiness, marking a significant shake-up in the military's top leadership. Driscoll's departure follows a public feud over who should lead the effort to reshape the Army.

Cyber Firms' AI Defense Push Sparks Scrutiny Over Commitments
More than 200 companies, including tech giants like Microsoft and Google, have joined forces to supercharge cyber defense capabilities and shield against AI-enabled attacks. They're calling for a united front to share threat intel, track progress, and swiftly contain attacks.

Threat Actors Exploit METR API Key, Drain $600,000 in AI Credits
A staggering $600,000 in AI credits vanished in a flash when an unknown attacker exploited a stolen API key, infiltrating a publicly accessible experiment and racking up a massive bill that was thankfully waived by the model provider. The shocking breach happened after a researcher inadvertently left an EC2 instance exposed, despite having Google authentication in place.

Russia-Aligned Hackers Inject Nuclear Prompt to Evade AI Analysis
Hackers have found a sneaky way to outsmart AI-powered security tools by injecting a provocative phrase, like a threat to create a nuclear weapon, into malicious code to disable analysis. This clever trick, dubbed GuardBreaker, tricks AI scanners into failing to examine the rest of the script.